CVE-2021-32603: SSRF
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-32603.
What is the severity of CVE-2021-32603?
CVE-2021-32603 has a severity rating of high.
Which software versions are affected by CVE-2021-32603?
FortiManager and FortiAnalyser GUI versions 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below are affected by CVE-2021-32603.
How does CVE-2021-32603 impact the system?
CVE-2021-32603 allows a remote and authenticated attacker to access unauthorized files and services on the system via a specifically crafted request.
Is there a fix available for CVE-2021-32603?
Yes, Fortinet has released patches to address the vulnerability. Please refer to the [FortiGuard Advisory](https://fortiguard.com/advisory/FG-IR-21-050) for more information.